Secunia Advisory SA37607Polipo Denial of Service Vulnerabilities
|
|||||||||||||||||||||||||||||||||||||||||||||||||||||||||
Description
Some vulnerabilities have been discovered in Polipo, which can be exploited by malicious people to cause a DoS (Denial of Service). 1) A vulnerability is caused due to a signedness error within the "httpClientDiscardBody()" function in client.c. This can be exploited to crash the service by sending HTTP requests with an overly large value in the "Content-Length" header. 2) The "httpParseHeaders()" function in http_parse.c does not properly parse certain "Cache-Control" headers, which can be exploited to crash the service by sending HTTP requests with a specially crafted "Cache-Control" header. The vulnerabilities are confirmed in version 1.0.4. Other versions may also be affected. Solution Provided and/or discovered by Deep Links Do you have additional information related to this advisory?Please provide information about patches, mitigating factors, new versions, exploits, faulty patches, links, and other relevant data by posting comments to this Advisory. You can also send this information to vuln@secunia.com
|
|||||||||||||||||||||||||||||||||||||||||||||||||||||||||
101 views | ![]() |
TYPO3 The official twitter tweet button for your page Extension Cross-Site Scripting Vulnerability![]() | |